The Opportunity
Chartwell Retirement Residences is seeking a Security Architect to join the Information Security team as a senior technical leader. In this role, you will define and drive enterprise security architecture strategy in support of Chartwell's multi-year information security roadmap and Zero Trust Architecture vision. You will translate business and risk objectives into secure, scalable technical designs across our identity, cloud, network, and endpoint environments - and act as the trusted security design authority for technology and business initiatives across the organization.
This is a hands-on architecture role: you will set standards and reference architectures, but you will also work directly in the platforms you design for, partnering with other members of the security, infrastructure, and application teams to see designs through to implementation.
Key Accountabilities
- Own and evolve Chartwell's enterprise security architecture, reference architectures, and design standards in alignment with the information security strategy and Zero Trust Architecture principles.
- Lead security design for identity and access management, including authentication, authorization, federation, privileged access, and conditional access design across Active Directory, ADFS and Entra ID environments.
- Mature network security architecture, including secure access (SSE/SASE), network segmentation, and least-privilege access models.
- Define and continuously improve the security posture of Microsoft 365 and Azure, including Purview (DLP, sensitivity labels, retention), Exchange Online, SharePoint Online, and Entra ID configuration baselines.
- Provide security design review and consultation for new projects, applications, cloud services, and infrastructure changes, embedding security requirements early in the lifecycle.
- Lead design of Agentic AI security strategy
- Develop and maintain security standards, patterns, and hardening baselines
- Partner with security operations on detection and response architecture, ensuring telemetry, logging, and control coverage across endpoints, identity, email, and network layers.
- Assess and advise on the security of third-party and SaaS solutions, including AI-enabled platforms, as part of vendor risk and technology intake processes.
- Contribute to incident response as a senior technical escalation point, and translate lessons learned into architectural improvements.
- Communicate architecture decisions, risks, and trade-offs clearly to technical teams and executive stakeholders, including contributions to board- and committee-level reporting.
Qualifications
Education:
- University/College degree in Computer Science
- Certificate in (or working towards) information security (CISSP, CISA, CSIM, CRISC)
Skills & Abilities:
- 10+ years of progressive experience in information security, with 5+ years in a security architecture or senior security engineering role.
- Deep expertise in identity and authorization: Entra ID / Azure AD, Active Directory, ADFS or modern federation (SAML, OIDC, WS-Federation), conditional access, MFA, and privileged access management.
- Strong working knowledge of zero trust network architecture and its practical application to networks, identity, endpoints, and data.
- Proven experience securing Microsoft 365 and Azure at enterprise scale, including Purview, and cloud security posture management.
- Experience designing and operating email security, web security, and endpoint detection and response controls in a layered defence model.
- Ability to produce clear architecture artifacts: reference architectures, design documents, standards, and threat models.
- Good understanding of evolving AI tools, MCPs and associated risks
- Strong communication skills, with the ability to influence stakeholders from engineers to executives.
Preferred Product Experience
- Cisco Umbrella / Cisco Secure Access (SWG, DNS security, secure client)
- Microsoft 365 security and compliance stack (Defender, Purview, Entra ID)
- Proofpoint (email protection, targeted attack protection)
- CrowdStrike Falcon (EDR, identity protection, exposure management, NG-SIEM)
Preferred background
- Relevant certifications such as CISSP, CISSP-ISSAP, SABSA, CCSP, or equivalent.
- Experience with security frameworks and risk methodologies (CIS Controls, NIST CSF, CIS RAM).
- Exposure to AI governance and securing AI-enabled or agentic platforms.
- University Degree in Computer Science or related discipline
Working Conditions
- Hybrid working arrangements with a minimum of 2 days in the office per week
- Occasional need to work outside of office hours
At Chartwell, we’re all about Making People’s Lives BETTER: the lives of our residents and their families, and the lives of our employees. Join an exceptional group of diverse, inspiring, and caring people who are empowered to provide personalized, human experiences for our residents and staff through the connections they make every day within our communities.
Chartwell’s commitment to diversity and inclusivity is a commitment to hiring people whose skills and abilities contribute the most to the success of the organization and who reflect the communities in which we live and work. We are an equal opportunity employer and welcome applications from a wide range of qualified candidates, including people with disabilities. If you have questions or require assistance with the application process, please email [email protected] or call 1-888-663-6448.
Chartwell may use artificial intelligence to assist in screening and assessing applicants for this position.
We thank all applicants for their interest, however, only those selected for further consideration will be contacted.